@achapman is it acceptable to add the Authorization header to Access-Control-Allow-Headers in the REST API?
Given the lack of response on this bug I'm closing it as this has been requested, and denied, before.